Florida
What Is the FDBR? Florida Digital Bill of Rights
Independently fact-checked against primary sources (last audited August 14, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of August 14, 2026. · 9 primary sources cited on this page. How we verify our legal content

The Florida Digital Bill of Rights (FDBR), codified at Fla. Stat. 501.701 et seq., is Florida's comprehensive consumer data privacy law. It was enacted as Senate Bill 262 (2023), signed by Governor Ron DeSantis on June 6, 2023, and took effect July 1, 2024, giving Florida residents rights to access, correct, delete, and port their personal data and to opt out of sale, targeted advertising, profiling, and certain data collection.
As of 2026, the FDBR is the narrowest comprehensive state privacy law in the country at its core: the central "controller" obligations reach only for-profit businesses that make more than $1 billion in global gross annual revenues and fit one of three big-technology profiles. A separate set of broader provisions in the same package reaches far more businesses, and the Florida Department of Legal Affairs enforces all of it with civil penalties of up to $50,000 per violation, triplable in defined cases.
Jurisdiction scope: This covers Florida's Florida Digital Bill of Rights (Fla. Stat. 501.701 et seq.). It is general legal information, not legal advice.
What the FDBR is: statute, enactment, and effective date
The Florida Digital Bill of Rights is Florida's first comprehensive consumer data privacy law. It is codified at Florida Statutes Sections 501.701 through 501.722, within Part V of the state's consumer protection chapter. The short title in 501.701 expressly states that the part "may be cited as the Florida Digital Bill of Rights."
The Florida Legislature passed it as Senate Bill 262 during the 2023 session. Governor Ron DeSantis signed the bill into law on June 6, 2023, and the act took effect July 1, 2024. As of 2026, that effective date has passed, so every covered business is now fully subject to the law and the Department of Legal Affairs is actively enforcing it.
SB 262 was framed politically around protecting consumers and especially children from large technology platforms. That framing is visible in the statute's structure: the headline obligations are aimed squarely at the largest companies, while a separate cluster of provisions reaches a much broader set of businesses. For the parent overview of Florida privacy obligations, see the Florida data privacy laws hub.
The $1 billion controller threshold: why the FDBR targets Big Tech
The FDBR's defining feature is the definition of "controller" in 501.702(9), which is the narrowest in the country. A business is a covered controller only if it is organized for profit, conducts business in this state, collects personal data about consumers, determines the purposes and means of processing that data alone or jointly with others, makes in excess of $1 billion in global gross annual revenues, and satisfies at least one of three additional prongs in 501.702(9)(a)6. The broader "conducts business in this state or produces a product or service used by residents of this state" language sits in the separate applicability provision at 501.703(1)(a), not in the controller definition, so a company with no Florida business presence does not become a controller merely because Floridians use its product.
The first prong, in 501.702(9)(a)6.a., is deriving 50 percent or more of its global gross annual revenues from the sale of advertisements online, including providing targeted advertising or the sale of ads online. This prong captures the largest ad-driven platforms.
The second prong, in 501.702(9)(a)6.b., is operating a consumer smart speaker and voice command component service with an integrated virtual assistant connected to a cloud computing service that uses hands-free verbal activation. The statute carves out a motor vehicle or a speaker or device associated with or connected to a vehicle operated by a motor vehicle manufacturer or its subsidiary or affiliate. This prong is aimed at major voice-assistant makers.
The third prong, in 501.702(9)(a)6.c., is operating an app store or a digital distribution platform that offers at least 250,000 different software applications for consumers to download and install. This prong reaches the dominant mobile app marketplaces.
The practical effect is that the FDBR's core controller obligations apply to only a handful of the very largest technology companies. A business that makes less than $1 billion globally, or that exceeds $1 billion but fits none of the three prongs, is not a "controller" and is outside the central duties of the law.

The broader provisions that reach far more businesses
It would be a serious mistake to read the FDBR as a Big-Tech-only statute and stop there. SB 262 created several provisions that apply well beyond the $1 billion controller, and Florida businesses of ordinary size must heed them.
First, the sale-of-sensitive-data consent rule in 501.715 prohibits a person meeting the controller definition's structural prongs in 501.702(9)(a)1.-3. from engaging in the sale of personal data that is sensitive data without prior consent from the consumer, or, for a known child, without the required authorization or compliance with the Children's Online Privacy Protection Act. Sensitive data is defined to include biometric data, so this functions as a sale-of-sensitive-biometric-data consent rule.
Second, the children's online protections in 501.1735 reach online platforms that provide an online service, product, game, or feature likely to be predominantly accessed by children, regardless of the $1 billion threshold. That section restricts processing a known child's personal data in ways that cause harm, prohibits certain dark patterns, and limits collecting a known child's precise geolocation without consent.
Third, SB 262 amended the breach-notification statute 501.171 to add biometric data (as defined in 501.702) and geolocation information to the definition of covered personal information, broadening data-breach duties for businesses generally. The bill also added 112.23, which restricts governmental entities from coordinating with social media platforms to remove or moderate content. Together these provisions mean the FDBR package touches many businesses that are not "controllers."

Consumer rights and the voice and facial recognition opt-out
Against a covered controller, Florida consumers hold the now-familiar suite of state privacy rights under 501.705: to confirm processing and access their personal data, to correct inaccuracies, to delete data, to obtain a portable copy, and to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects.
The FDBR adds two opt-out rights that set it apart. Under 501.705(2)(f), a consumer may opt out of the collection of sensitive data, including precise geolocation data. Under 501.705(2)(g), a consumer may opt out of the collection of personal data collected through the operation of a voice recognition or facial recognition feature.
Those two collection opt-outs are distinctive. Most state privacy laws let consumers opt out of selling or using sensitive data, but Florida lets a consumer opt out of its collection in the first place, and singles out voice and facial recognition features by name. The FDBR consumer rights guide walks through every right, the response window, and the appeal process in detail.
FDBR vs. CCPA: the key differences
Florida's FDBR and California's CCPA are frequently compared by companies that operate nationally. The state data privacy law comparison page covers the broader multistate picture, but several differences between the FDBR and California's CCPA stand out.
| Feature | Florida FDBR | California CCPA/CPRA |
|---|---|---|
| Core coverage threshold | For-profit, over $1B global revenue AND one of three big-tech prongs (501.702(9)) | $26.625M revenue (CPI-adjusted, eff. Jan 1, 2025), OR 100,000 consumers, OR 50% revenue from data sales |
| Reach of core duties | Narrowest in the country; a handful of large platforms | Broad; many mid-size and large businesses |
| Distinctive opt-out | Opt out of voice or facial recognition collection (501.705(2)(g)) | Right to limit use of sensitive personal information |
| Sensitive data | Opt-in consent to process (501.71(2)(d)); opt-out of collection (501.705(2)(f)) | Opt-out right to limit |
| Private right of action | None (501.72(8)) | Limited, for certain data breaches |
| Enforcer | Department of Legal Affairs only (501.72) | California Privacy Protection Agency and Attorney General |
The most consequential difference is coverage. California's thresholds are disjunctive and reach a broad swath of businesses, while Florida's core controller test is conjunctive and aimed at only the largest technology firms. The second major difference is Florida's voice and facial recognition collection opt-out, which California does not match in the same form. The takeaway for a multistate business is that being outside the FDBR's controller definition does not necessarily mean being outside the CCPA, and the FDBR's broader provisions can still apply.
Related guides
- Florida data privacy laws parent hub
- FDBR consumer rights
- FDBR compliance checklist
- State data privacy law comparison
- What is the CCPA?
More Florida Laws
Frequently Asked Questions
What is the Florida Digital Bill of Rights?
The Florida Digital Bill of Rights (FDBR) is Florida's comprehensive consumer data privacy law, codified at Fla. Stat. 501.701 to 501.722. It was enacted as Senate Bill 262, signed by Governor Ron DeSantis on June 6, 2023, and took effect July 1, 2024. It gives Florida residents rights over their personal data and imposes core obligations on a narrow set of very large technology companies, plus broader provisions that reach more businesses.
When did the Florida Digital Bill of Rights take effect?
The FDBR took effect July 1, 2024, more than a year after it was signed on June 6, 2023. As of 2026, the effective date has passed, the law is fully in force, and the Florida Department of Legal Affairs has begun publishing annual enforcement reports and pursuing enforcement actions under it.
Who has to comply with the Florida Digital Bill of Rights?
The core controller obligations under 501.702(9) apply only to a for-profit business that makes more than $1 billion in global gross annual revenues AND meets one of three prongs: 50 percent or more of revenue from online advertising; operating a consumer smart speaker and voice assistant service; or operating an app store or digital distribution platform with at least 250,000 different applications. This is the narrowest controller test of any state privacy law.
Why is the FDBR called the narrowest privacy law in the country?
Because its core controller definition in 501.702(9) requires more than $1 billion in global revenue plus one of three big-technology prongs, the central obligations reach only a handful of the largest platforms. Most other state laws cover businesses based on far lower revenue or data-volume figures, so the FDBR's central duties apply to a much smaller group.
Does the FDBR apply to small and mid-size Florida businesses?
Generally not for the core controller obligations, because those require more than $1 billion in global revenue under 501.702(9). But broader provisions do reach smaller businesses: the children's online protections in 501.1735 apply to platforms likely to be predominantly accessed by children, and amendments to the breach-notification statute 501.171 add biometric and geolocation data for businesses generally.
What is the voice and facial recognition opt-out?
Under 501.705(2)(g), a Florida consumer may opt out of the collection of personal data collected through the operation of a voice recognition or facial recognition feature. This is a distinctive FDBR right that singles out those biometric features by name, in addition to the broader right under 501.705(2)(f) to opt out of the collection of sensitive data, including precise geolocation.
How is the FDBR different from the CCPA?
The FDBR's core coverage is far narrower: it requires more than $1 billion in global revenue plus a big-tech prong (501.702(9)), while the CCPA reaches businesses on revenue, data volume, or data-sale revenue alone. The FDBR adds a voice and facial recognition collection opt-out that California does not match in the same form. Both treat sensitive data specially, but the FDBR uses opt-in to process and an opt-out of collection, and neither has a general private right of action under the FDBR (501.72(8)).
Who enforces the Florida Digital Bill of Rights?
The Florida Department of Legal Affairs, part of the Attorney General's office, has exclusive enforcement authority under 501.72. There is no private right of action (501.72(8)). The department may grant a discretionary 45-day cure period, and civil penalties run up to $50,000 per violation, triplable for violations involving a known child, failure to delete or correct after a request, or continued sale or sharing after an opt-out.
Updates
Corrected the FDBR controller test: the "produces a product or service used by Florida residents" alternative belongs to the separate applicability provision (Fla. Stat. 501.703(1)(a)), not the controller definition, and the missing "determines the purposes and means of processing" element was added.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Corrected the FDBR's voice/facial-recognition and sensitive-data opt-out citations from Fla. Stat. 501.705(1) to the correct 501.705(2), across KeyTakeaways, body text, the FDBR-vs-CCPA comparison table, and the FAQ.
Governing law re-checked for recent changes
Reviewed and approved by an editor
The Law Behind This Article
This article rests on the statutory provisions below, held in our own legal record and retrieved from the official source. Tap a section to read the operative text.
Florida Statutes
§ 501.705Consumer rights.In forcecited in 5 of our articles
(1) A consumer is entitled to exercise the consumer rights authorized by this section at any time by submitting a request to a controller which specifies the consumer rights that the consumer wishes to exercise. With respect to the processing of personal data belonging to a known child, a parent or legal guardian of the child may exercise these rights on behalf of the child. (2) A controller shall comply with an authenticated consumer request to exercise any of the following rights:(a) To confirm whether a controller is processing the consumer’s personal data and to access the personal data. (b) To correct inaccuracies in the consumer’s personal data, taking into account the nature of the personal data and the purposes of the processing of the consumer’s personal data. (c) To delete any or all personal data provided by or obtained about the consumer. (d) To obtain a copy of the consumer’s personal data in a portable and, to the extent technically feasible, readily usable format if the data is available in a digital format. (e) To opt out of the processing of the personal data for purposes of:1. Targeted advertising; 2. The sale of personal data; or 3.
Official text (excerpt) · last checked 2026-08-28 · Read the full text in our law library · Verify at leg.state.fl.us
Also relied on in: Florida Data Privacy Laws: Digital Bill of Rights & Breach Rules (2026), Florida Biometric Privacy Laws: Collection, Consent & Penalties (2026), FDBR Compliance Checklist: Florida Data Privacy
§ 501.702Definitions.In forcecited in 4 of our articles
As used in this part, the term:(1) “Affiliate” means a legal entity that controls, is controlled by, or is under common control with another legal entity or that shares common branding with another legal entity. For purposes of this subsection, the term “control” or “controlled” means any of the following:(a) The ownership of, or power to vote, more than 50 percent of the outstanding shares of any class of voting security of a company. (b) The control in any manner over the election of a majority of the directors or of individuals exercising similar functions. (c) The power to exercise controlling influence over the management of a company. (2) “Aggregate consumer information” means information that relates to a group or category of consumers from which the identity of an individual consumer has been removed and is not reasonably capable of being directly or indirectly associated or linked with any consumer, household, or device. The term does not include information about a group or category of consumers used to facilitate targeted advertising or the display of ads online. The term does not include personal information that has been deidentified.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
Also relied on in: FDBR Consumer Rights: Florida Data Privacy Rights
§ 501.715Requirements for sensitive data.In forcecited in 4 of our articles
(1) A person who meets the requirements of s. 501.702(9)(a)1.-3. for the definition of a controller may not engage in the sale of personal data that is sensitive data without receiving prior consent from the consumer or, if the sensitive data is of a known child, without processing that data with the affirmative authorization for such processing by a known child who is between 13 and 18 years of age or in accordance with the Children’s Online Privacy Protection Act, 15 U.S.C. ss. 6501 et seq. for a known child under the age of 13. (2) A person in subsection (1) who engages in the sale of personal data that is sensitive data must provide the following notice: “NOTICE: This website may sell your sensitive personal data.” (3) A person who violates this section is subject to the penalty imposed under s. 501.72.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
§ 501.703Applicability.In forcecited in 2 of our articles
(1) This part applies only to a person who:(a) Conducts business in this state or produces a product or service used by residents of this state; and (b) Processes or engages in the sale of personal data. (2) This part does not apply to any of the following:(a) A state agency or a political subdivision of the state. (b) A financial institution or data subject to Title V, Gramm-Leach-Bliley Act, 15 U.S.C. ss. 6801 et seq. (c) A covered entity or business associate governed by the privacy, security, and breach notification regulations issued by the United States Department of Health and Human Services, 45 C.F.R. parts 160 and 164, established under the Health Insurance Portability and Accountability Act of 1996, 42 U.S.C. ss. 1320d et seq., and the Health Information Technology for Economic and Clinical Health Act, Division A, Title XIII and Division B, Title IV, Pub. L. No. 111-5. (d) A nonprofit organization. (e) A postsecondary education institution. (f) The processing of personal data:1. By a person in the course of a purely personal or household activity. 2. Solely for measuring or reporting advertising performance, reach, or frequency.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
§ 501.72Enforcement and implementation by the Department of Legal Affairs.In forcecited in 5 of our articles
(1) A violation of this part is an unfair and deceptive trade practice actionable under part II of this chapter solely by the Department of Legal Affairs. If the department has reason to believe that a person is in violation of this section, the department may, as the enforcing authority, bring an action against such person for an unfair or deceptive act or practice. For the purpose of bringing an action pursuant to this section, ss. 501.211 and 501.212 do not apply. In addition to other remedies under part II of this chapter, the department may collect a civil penalty of up to $50,000 per violation. Civil penalties may be tripled for any of the following violations:(a) A violation involving a Florida consumer who is a known child. A controller that willfully disregards the consumer’s age is deemed to have actual knowledge of the consumer’s age. (b) Failure to delete or correct the consumer’s personal data pursuant to this section after receiving an authenticated consumer request or directions from a controller to delete or correct such personal data, unless an exception to the requirements to delete or correct such personal data under this section applies.
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
§ 501.701Short title.In forcecited in 6 of our articles
This part may be cited as the “Florida Digital Bill of Rights.”
Official text (excerpt) · last checked 2026-07-28 · Read the full text in our law library · Verify at leg.state.fl.us
Also relied on in: Florida Employee Monitoring Laws: Employer Rules (2026)
Explore the law
This article also draws on these acts and chapters (opening at their first section): Florida Statutes § 501.001 (Florida Anti-Tampering Act.)
Related law for further reading — not part of this article’s citations.
Search our full record of US law — 2.1 million sections, every state + federal →
Sources and References
- Fla. Stat. 501.701 to 501.722: Florida Digital Bill of Rights (2024 Florida Statutes, Chapter 501, Part V)(flsenate.gov).gov
- Fla. Stat. 501.701: Short title (Florida Digital Bill of Rights)(flsenate.gov).gov
- Fla. Stat. 501.702: Definitions, including the Controller definition and $1 billion threshold(flsenate.gov).gov
- Fla. Stat. 501.703: Applicability(flsenate.gov).gov
- Fla. Stat. 501.705: Consumer rights, including voice and facial recognition opt-out(flsenate.gov).gov
- Fla. Stat. 501.715: Requirements for sensitive data (sale-of-sensitive-data consent)(flsenate.gov).gov
- Fla. Stat. 501.72: Enforcement and implementation by the Department of Legal Affairs(flsenate.gov).gov
- Florida Senate Bill 262 (2023): Enrolled Bill Text(flsenate.gov).gov
- Florida Department of Legal Affairs: Florida Digital Bill of Rights Annual Enforcement Report(myfloridalegal.com).gov